Directing Cidlog Messages To Syslog - Cisco IPS 7.1 Installation Manual

Intrusion prevention system appliance and module
Table of Contents

Advertisement

Troubleshooting the Appliance
For More Information
To learn more about the IPS Logger service, refer to Logger.

Directing cidLog Messages to SysLog

It might be useful to direct cidLog messages to syslog.
To direct cidLog messages to syslog, follow these steps:
Go to the idsRoot/etc/log.conf file.
Step 1
Make the following changes:
Step 2
a.
b.
Note
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.1
E-50
Set [logApp]
enabled=false
Comment out the
enabled=true
Set [drain/main]
type=syslog
The following example shows the logging configuration file:
timemode=local
;timemode=utc
[logApp]
;enabled=true
;-------- FIFO parameters --------
fifoName=logAppFifo
fifoSizeInK=240
;-------- logApp zone and drain parameters --------
zoneAndDrainName=logApp
fileName=main.log
fileMaxSizeInK=500
[zone/Cid]
severity=warning
drain=main
[zone/IdsEventStore]
severity=debug
drain=main
[drain/main]
type=syslog
The syslog output is sent to the syslog facility local6 with the following correspondence to syslog
message priorities:
LOG_DEBUG,
//
LOG_INFO,
LOG_WARNING,
//
warning
LOG_ERR,
//
LOG_CRIT
//
Make sure that your /etc/syslog.conf has that facility enabled at the proper priority.
because
enabled=false
debug
//
timing
error
fatal
Appendix E
is the default.
Troubleshooting
OL-24002-01

Advertisement

Table of Contents
loading

Table of Contents